begin
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
SearchRootkit(true, true);
SetAVZGuardStatus(True);
TerminateProcessByName('c:\documents and settings\all users\application data\{3a57d343-a5b0-bafa-db95-f3a1465e046e}\251842.exe');
QuarantineFile('c:\documents and settings\all users\application data\{377A9B92-ED61-B7D7-DB95-F3A1465E046E}\9ac54b0d.exe','');
QuarantineFile('C:\Documents and Settings\All Users\Application Data\{4EFE4282-F955-F529-222D-0B60C46F49F4}\F0E450A9-474F-E702-D742-7C5ABA2CC553.exe','');
QuarantineFile('c:\documents and settings\Андрей\application data\{D3C9C03C-D15F-88D4-34C2-26FE06E69261}\7e7610a3.exe','');
QuarantineFile('C:\Documents and Settings\Андрей\Application Data\WindowsUpdate\mobsync.exe','');
QuarantineFile('C:\Documents and Settings\Андрей\Application Data\WindowsUpdate\System.exe','');
DeleteFile('C:\Documents and Settings\Андрей\Application Data\WindowsUpdate\System.exe','32');
DeleteFile('C:\Documents and Settings\Андрей\Application Data\WindowsUpdate\mobsync.exe','32');
DeleteFile('c:\documents and settings\Андрей\application data\{D3C9C03C-D15F-88D4-34C2-26FE06E69261}\7e7610a3.exe','32');
DeleteFile('C:\Documents and Settings\All Users\Application Data\{4EFE4282-F955-F529-222D-0B60C46F49F4}\F0E450A9-474F-E702-D742-7C5ABA2CC553.exe','32');
DeleteFile('c:\documents and settings\all users\application data\{377A9B92-ED61-B7D7-DB95-F3A1465E046E}\9ac54b0d.exe','32');
QuarantineFile('c:\documents and settings\all users\application data\{3a57d343-a5b0-bafa-db95-f3a1465e046e}\251842.exe', '');
QuarantineFile('C:\Documents and Settings\Application Data\GVMTKIX.exe', '');
QuarantineFile('C:\Documents and Settings\Андрей\Local Settings\Application Data\svshost\svshost.exe', '');
QuarantineFile('C:\Documents and Settings\Application Data\TJAOMV.exe', '');
QuarantineFile('C:\Documents and Settings\Application Data\XAVNJJZY.exe', '');
QuarantineFile('C:\DOCUME~1\ALLUSE~1\APPLIC~1\1c89c365\7520cf2e.dll', '');
ExecuteFile('schtasks.exe', '/delete /TN "C:\WINDOWS\Tasks\GVMTKIX.job" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "C:\WINDOWS\Tasks\svshost.job" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "C:\WINDOWS\Tasks\TJAOMV.job" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "C:\WINDOWS\Tasks\XAVNJJZY.job" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "C:\WINDOWS\Tasks\{B1AA8F04-0894-F922-12CF-066671D0E46D}.job" /F', 0, 15000, true);
DeleteFile('c:\documents and settings\all users\application data\{3a57d343-a5b0-bafa-db95-f3a1465e046e}\251842.exe', '32');
DeleteFile('C:\Documents and Settings\Application Data\GVMTKIX.exe', '32');
DeleteFile('C:\Documents and Settings\Андрей\Local Settings\Application Data\svshost\svshost.exe', '32');
DeleteFile('C:\Documents and Settings\Application Data\TJAOMV.exe', '32');
DeleteFile('C:\Documents and Settings\Application Data\XAVNJJZY.exe', '32');
DeleteFile('C:\DOCUME~1\ALLUSE~1\APPLIC~1\1c89c365\7520cf2e.dll', '32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Windows System Installer');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows NT\CurrentVersion\Winlogon', 'Taskman');
BC_ImportALL;
ExecuteSysClean;
BC_Activate;
ExecuteWizard('SCU', 2, 3, true);
RebootWindows(true);
end.